ligolo-ng
Fail
Audited by Snyk on Apr 16, 2026
Risk Level: CRITICAL
Full Analysis
HIGH W007: Insecure credential handling detected in skill instructions.
- Insecure credential handling detected (high risk: 1.00). The prompt includes an explicit plaintext credential example (e.g., "evil-winrm -i ... -u admin -p pass") and demonstrates passing passwords on the command line, which requires embedding secrets verbatim in generated commands/outputs.
CRITICAL E006: Malicious code pattern detected in skill scripts.
- Malicious code pattern detected (high risk: 1.00). This skill documents an explicit reverse-tunneling backdoor (proxy + agent) intended to be deployed on a compromised pivot host (including instructions to upload/run agents, ignore TLS certs, enable persistence/Windows service install, create TUN interfaces, and add port-forwarding) — behavior that directly enables unauthorized remote access, lateral movement, and data exfiltration.
MEDIUM W013: Attempt to modify system services in skill instructions.
- Attempt to modify system services in skill instructions detected (high risk: 1.00). The prompt explicitly instructs privileged system modifications—creating TUN interfaces, running sudo ip tuntap/ip link/ip route commands, starting privileged listeners, and references agent persistence/Windows service install—so it directs the agent to change the machine's state and require/seek elevated privileges.
Issues (3)
W007
HIGHInsecure credential handling detected in skill instructions.
E006
CRITICALMalicious code pattern detected in skill scripts.
W013
MEDIUMAttempt to modify system services in skill instructions.
Audit Metadata